U.S. federal agencies say Iranian-backed hackers are continuing to infiltrate industrial control systems of U.S. water and energy suppliers, posing a risk of downtime and operational disruptions. This latest was jointly issued by the FBI, NSA, Department of Energy, and the Cybersecurity and Infrastructure Security Agency (CISA).
Attack Targeting Network Controller
Federal agencies say attackers are targeting programmable logic controllers (PLCs) in internet-connected commercial networks. These devices are commonly used for industrial field control. Once hackers gain access, they could tamper with displayed data, potentially causing downtime or business disruptions.
The latest notification expands the scope of affected equipment. In addition to the previously identified Rockwell controllers, related industrial control products from Schneider Electric and Siemens are now also included in the . The notification states that, theoretically, all industrial control systems exposed to the internet could be affected.
Critical shutdowns and alarms were rewritten
According to the FBI, hackers compromised a critical infrastructure provider and modified the controller's programming logic, disabling processes responsible for critical downtime and s. Federal agencies stated that this could have left the system in an insecure state, preventing operators from promptly detecting anomalies from s.
U.S. agencies believe these activities are intended to have a destructive impact within the United States and are linked to the ongoing conflict between Iran, the United States, and Israel. Compared to more common intelligence theft or leaks, this emphasizes the more direct risks of interference and disruption.
The attack range has continued to expand recently.
The report mentions that recent actions by Iranian hackers have gone beyond traditional espionage. A notable example is the attack on the US medical technology company Stryker, which allowed the hacking group Handala to remotely erase tens of thousands of employee devices.
In June of this year, Handala also claimed responsibility for a data breach at California water company Cal Water, stating that it could have interfered with water supply, but provided no evidence. Cal Water stated at the time that it had found no evidence of unauthorized access to its operational network responsible for water supply control.
This indicates that the U.S. government is prioritizing industrial control system security as a key focus of its cybersecurity efforts. As attacks expand from single vendors to a wider range of equipment brands, water and energy operators are facing increasing pressure to investigate and harden their systems.












